T1074.001 - Local Data Staging
Sub-technique
Tattiche:
Collection
Collection
Piattaforme:
ESXi Linux macOS Windows
ESXi Linux macOS Windows
Rilevamento:
Not specified
Not specified
Description:
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as [Archive Collected Data](https://attack.mitre.org/techniques/T1560). Interactive command shells may be used, and common functionality within [cmd](https://attack.mitre.org/software/S0106) and bash may be used to copy data into a staging location.
Adversaries may also stage collected data in various available formats/locations of a system, including local storage databases/repositories or the Windows Registry.(Citation: Prevailion DarkWatchman 2021)
Adversaries may also stage collected data in various available formats/locations of a system, including local storage databases/repositories or the Windows Registry.(Citation: Prevailion DarkWatchman 2021)
Usato da Attori (20)
APT3
Nation-state
Nation-state
APT28
Nation-state
Nation-state
Lazarus Group
Nation-state
Nation-state
APT5
Unknown
Unknown
Kimsuky
Nation-state
Nation-state
MuddyWater
Nation-state
Nation-state
MUSTANG PANDA
Nation-state
Nation-state
INDRIK SPIDER
Unknown
Unknown
WIZARD SPIDER
Nation-state
Nation-state
APT39
Unknown
Unknown
FIN5
Unknown
Unknown
GALLIUM
Unknown
Unknown
TeamTNT
Unknown
Unknown
BackdoorDiplomacy
Unknown
Unknown
FIN13
Unknown
Unknown
Volt Typhoon
Unknown
Unknown
UNC3886
Unknown
Unknown
Dragonfly
Unknown
Unknown
Patchwork
Unknown
Unknown
Leviathan
Unknown
Unknown
Malware (20)
Exaramel for Windows other
NOKKI other
KOPILUWAK other
VersaMem other
PAKLOG other
Ursnif other
FrameworkPOS other
InvisibleFerret other
RainyDay other
AppleSeed other
NETWIRE other
Turian other
Machete other
PowerLess other
Prikormka other
Mafalda other
AuTo Stealer other
SombRAT other
FLASHFLOOD other
LoFiSe other
Metadata
| MITRE ID: | T1074.001 |
| STIX ID: | attack-pattern--1c34f7aa-9341-... |
| Piattaforme: | ESXi, Linux, macOS, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |